Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×

Submission + - Windows vulnerability reported by the NSA exploited to install Russian malware (arstechnica.com)

echo123 writes: Kremlin-backed hackers have been exploiting a critical Microsoft vulnerability for four years in attacks that targeted a vast array of organizations with a previously undocumented tool, the software maker disclosed Monday.

When Microsoft patched the vulnerability in October 2022—at least two years after it came under attack by the Russian hackers—the company made no mention that it was under active exploitation. As of publication, the company’s advisory still made no mention of the in-the-wild targeting. Windows users frequently prioritize the installation of patches based on whether a vulnerability is likely to be exploited in real-world attacks.

On Monday, Microsoft revealed that a hacking group tracked under the name Forest Blizzard has been exploiting CVE-2022-38028 since at least June 2020—and possibly as early as April 2019. The threat group—which is also tracked under names including APT28, Sednit, Sofacy, GRU Unit 26165, and Fancy Bear—has been linked by the US and the UK governments to Unit 26165 of the Main Intelligence Directorate, a Russian military intelligence arm better known as the GRU. Forest Blizzard focuses on intelligence gathering through the hacking of a wide array of organizations, mainly in the US, Europe, and the Middle East.

Microsoft representatives didn't respond to an email asking why the in-the-wild exploits are being reported only now.

Monday’s advisory provided additional technical details:

Read the rest at ArsTechnica.

Submission + - Voyager 1 Is Communicating Well Again (scientificamerican.com)

fahrbot-bot writes: Scientific American is reporting that after [5] months of nonsensical transmissions from humanity’s most distant emissary, NASA’s iconic Voyager 1 spacecraft is finally communicating intelligibly with Earth again.

When the latest communications glitch occurred last fall, scientists could still send signals to the distant probe, and they could tell that the spacecraft was operating. But all they got from Voyager 1 was gibberish—what NASA described in December 2023 as “a repeating pattern of ones and zeros.” The team was able to trace the issue back to a part of the spacecraft’s computer system called the flight data subsystem, or FDS, and identified that a particular chip within that system had failed.

Mission personnel couldn’t repair the chip. They were, however, able to break the code held on the failed chip into pieces they could tuck into spare corners of the FDS’s memory, according to NASA. The first such fix was transmitted to Voyager 1 on April 18. With a total distance of 30 billion miles to cross from Earth to the spacecraft and back, the team had to wait nearly two full days for a response from the probe. But on April 20 NASA got confirmation that the initial fix worked. Additional commands to rewrite the rest of the FDS system’s lost code are scheduled for the coming weeks, according to the space agency, including commands that will restore the spacecraft’s ability to send home science data.

Also: Voyager 1 is sending data back to Earth for the first time in 5 months and NASA's Voyager 1 spacecraft finally phones home after 5 months of no contact

Submission + - Voyager 1 resumes sending information (nasa.gov)

quonset writes: Just over two weeks ago, NASA figured out why its Voyager 1 spacecraft stopped sending useful data. They suspected corrupted memory in its flight data system (FDS) was the culprit. Today, for the first time since November, Voyager 1 is sending useful data about its health and the status of its onboard systems back to NASA. How did NASA accomplish this feat of long distance repair? They broke up the code into smaller pieces and redistributed them throughout the memory. From NASA:

So they devised a plan to divide the affected code into sections and store those sections in different places in the FDS. To make this plan work, they also needed to adjust those code sections to ensure, for example, that they all still function as a whole. Any references to the location of that code in other parts of the FDS memory needed to be updated as well.

The team started by singling out the code responsible for packaging the spacecraft’s engineering data. They sent it to its new location in the FDS memory on April 18. A radio signal takes about 22 ½ hours to reach Voyager 1, which is over 15 billion miles (24 billion kilometers) from Earth, and another 22 ½ hours for a signal to come back to Earth. When the mission flight team heard back from the spacecraft on April 20, they saw that the modification worked: For the first time in five months, they have been able to check the health and status of the spacecraft.

During the coming weeks, the team will relocate and adjust the other affected portions of the FDS software. These include the portions that will start returning science data.

Comment Re:Lead By Example (Score 2) 147

I don't see it. For example, cell phone records are only recorded and accessible via warrant, and by presenting that warrant to a provider directly. Same could be done with E2EE data if forced through the cell phone provider's networks.

That would mean an end to E2EE APIs on cell phones and other devices, which may be practically impossible at this point.

Edward Snowden showed that this is not as true as you seem to think it is.

LK

Comment Re:Lead By Example (Score 2) 147

Oh dear lord, the hyperbole. We allow law enforcement access to all other forms of communication with a lawful warrant. So should this particular technology be exempt from that?

Then, let them serve the warrant.

What is different is that for the first time in human history, it's not only possible but it's practical to have encrypted communications that no one can access except for the intended recipient.

All of "the most heinous of crimes" take place in the real world, there is some physical action that can be detected and punished. I don't care if this makes the job of law enforcement harder. I want law enforcement to be a difficult and time consuming job. Idle and bored cops tend to find ways to fill their time and it's never good.

LK

Comment Alarmists have historically been wrong. (Score 0) 170

People who waste their life away with worries and panic are not part of the solution. Buy solar panels, switch to higher efficiency machines, get a bicycle, use the train. See if your power company has a plan based on renewables. Plant trees, vines, bushes, buy flower pots or even a cactus. Do something OTHER than sitting on your ass with your armchair activism and annoying the silent but hard-working people who invest their whole lives into becoming greener.

Comment Re:Sure, let someone else be the gatekeeper (Score 0) 162

I've tried linux on my spouse's machine. It is not a desktop OS that my family can use. Either Windows or MacOS are the only thing that works reliably and intuitively enough to perform the common tasks my family uses their computers for.

Windows was my go-to desktop on their machines as MacOS has the Apple Tax on hardware and they very much own the machine due to the need for appleID. But now Microsoft has basically done the same.

At this point, on slashdot, this will sound like I'm trolling, but I truly am not... I want to know what distros of Linux ACTUALLY are stable enough, and intuitive enough to have the non-technical-savvy (aka normal/average) person use it without being frustrated? So far, every attempt to switch to linux has resulted in violent rage from one or more of my family members because something just doesn't work.

Comment Re:8GB is only to claim lower starting price... (Score 1) 461

I don't know about real Macs, but I have a Hackintosh that's ... um, OSX 10.8, on a midrange i7 with 8GB RAM and a fast SSD, and even doing nothing much (file manager, system settings and the like, no browser) it was sluggish to occasionally painful. Gave the system 32GB and suddenly it was much better.

If a version of OSX however-many-years-old is that bad with 8GB, I can't imagine current-OSX being pleasant.

Slashdot Top Deals

New York... when civilization falls apart, remember, we were way ahead of you. - David Letterman

Working...